WorkOS Pipes is the easiest way to add integrations to your apps and agents. 🤖
One API connects you to >100 SaaS services with pre-built OAuth flows, UI widgets, and more. 🚀
Fast and free. Try it now: https://t.co/18I1aebmc7
Today WorkOS is launching auth.md
An open protocol for agents to register for services on the web.
We're partnering with @Cloudflare and @Firecrawl as some of the first providers.
Why did we build this? And why now? 🧵
I wrote about how Login CSRF works — and how to design authentication flows that eliminate this class of risk.
If you build auth, this is worth understanding:
🔗 https://t.co/eAEk1ql23B
Have you heard someone say “Login See-surf”?
It’s actually Login CSRF -- and it’s one of the most misunderstood authentication attacks.
Let’s pull the thread 👇
In a Login CSRF attack, a user can be silently logged into the wrong account — without realizing it.
No malware.
No brute force.
Just a confused human in the loop.
Every cyberattack begins — and ends — with a human being.
With AI, attackers can generate pixel-perfect login flows in minutes.
But Login CSRF doesn’t require stealing passwords.
It exploits how authentication context is handled.
Enterprise Ready Conf is back this October! 🔥
A one-day conference for founders and leaders building enterprise SaaS and AI. Learn the playbooks from companies achieving breakout growth.
You won't want to miss it!
📍 SFJAZZ | October 22
🎟️ Register today for early pricing
MCP Night 2.0 is next week! 🕺🪩💃
This is the ultimate event for hundreds of developers building at the cutting edge of AI
Speakers from @OpenAI@AnthropicAI@Cursor_AI@GitHub@WorkOS and more 😉
🗓️ Thursday August 7
📍The Regency Ballroom
🎟️ RSVP required (link below)
How long does it take to deploy an MCP server…
🔐 secure it with WorkOS @AuthKit
🧪 test it in Cloudflare's AI playground
🧑💻 use it in Cursor
@chantastic thought it'd take all day. Nope, just 3 minutes! Video below 👇
📅 Save the Date: May 14 | MCP Night
A special, one-night event for those shaping the future of AI and MCP—demos, discussions, and developers.
Join us at the Exploratorium in San Francisco!
Register below ⬇️
WorkOS Launch Week - Day 1
🌟 WorkOS Connect 🌟
"Sign in with [Your App]"
Enable third-party developers and agents to connect via OAuth.
Identity Delegation
Integrate directly with apps that support federated login.
Machine-to-Machine Tokens (M2M)
Provide secure access to your API via the OAuth 2.0 client credentials flow
Full details in linked blog post 👇
🚨 Security Alert 🚨
WorkOS is disclosing a critical SAML authentication bypass in xml-crypto and Node.js libraries.
This flaw allows attackers to forge SAML responses, potentially granting unauthorized access to any user account in affected applications—including admin accounts—without any user interaction. This enables full account takeovers.
WorkOS customers are safe and were not impacted.
Any service using xml-crypto or a Node.js SAML implementation using it should update immediately to the latest version.
Full blog post with technical details 👇
WorkOS Customer Week day 3! @Perplexity_ai 🚀
Have a question? Just ask Perplexity. And if you’re at work, you can ask Perplexity Enterprise Pro — powered by @WorkOS.
Perplexity is building the future of search and we are thrilled to be a small part of their journey! 💙
WorkOS Customer Week day 2! @Cursor_ai 🚀
Cursor’s entire user identity layer is powered by @WorkOS, from signup to SSO, enabling them to quickly scale to even the largest enterprise customers.
Thank you Cursor team - We’re excited to support your incredible growth! 📈
Today kicks off WorkOS Customer Week! First up: @OpenAI 🚀
WorkOS powers enterprise auth and user management for ChatGPT Enterprise and the API platform—both scaling extremely fast.
We are thrilled to support your mission to develop safe AGI. Thank you for trusting @WorkOS 🙌